๐Ÿ” CVE Alert

CVE-2026-101904

UNKNOWN 0.0

Axios: Header Injection via Inherited headers After Minimal Interceptor

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0.

CWE CWE-74 CWE-1321
Vendor axios
Product axios
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
>= 1.0.0, < 1.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32 github.com: https://github.com/axios/axios/pull/11141 github.com: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a github.com: https://github.com/axios/axios/releases/tag/v1.20.0